Showing posts with label Defense in Depth. Show all posts
Showing posts with label Defense in Depth. Show all posts

Thursday, September 22, 2016

Reader Comment – Defense in Depth

Last night Dave Kuipers, a long-time member of the ICS cybersecurity team at Idaho National Labs, posted a comment to my blog post about the recent update of the ICS-CERT defense in depth paper. His lengthy comment provides some additional background information about how the team at INL considered the use of safety systems and operator response as part of the ICS defense in depth strategy. His comment is thoughtful and well worth reading.

I am a little concerned with the comment about ‘throwing out the baby with the bathwater’ that was included in his response because it would seem to indicate that the points that I was trying to make in my post may have been misunderstood. And I need to address my side of that communication problem.

First, I obviously did not make clear enough that I was not disparaging the technical aspects of the lengthy and well thought out paper. Defense in depth is the only way that an organization can have any hope of defending any sort of computer based system, particularly industrial control systems. I did not address the technical merits of the paper in my blog post because I do not have the technical background to do more than address the highlights. Those technical merits should be addressed by control system security experts.

My post addressed what thought was an insufficient level of attention to another area of the defense of system that uses the control system, safety systems and operator response. To be fair, this is not actually a cybersecurity defense, it is more appropriately a defense of the higher level system of which the ICS is an important component. As such, in hind sight, Dave’s comments are really appropriate.

In the ICS security community there is a great deal of deserved attention paid to the security aspects of the control system components. This is very important and certainly worthwhile. This technical focus, however, leads to a very distressing picture of the security of the businesses that rely on the use of industrial control systems. The history of poor security design and integration of control systems has left us with a legacy of systems that have porous security at best leaving industry with little hope of security for their systems in the foreseeable future.


People need to remember, however, and I would like to see ICS-CERT be more active in spreading this word, that industrial control systems do not operate in a vacuum. While connecting ICS to business systems have made the control systems arguably more vulnerable, other business processes help mitigate some of those vulnerabilities. If the control system security committee feels free to bemoan the decreased security that accompanies business system linkage, they also need to acknowledge and work with the business processes that help protect against the worst consequences of cyber insecurity. Safety systems and operator training are two of those processes that deserve mention, consideration and integration into control system security planning. This would add yet another dimension to defense in depth.

Monday, October 14, 2013

ICS-CERT Defense in Depth Paper

I was more than a little surprised this afternoon when I saw the following listed on the ICS-CERT web page:

Recently Published
·         Abstract: Defense-in-Depth RP
10/14/2013 - 12:24
[NOTE: As of 11:30 CDT, 10-15-13 This link has been removed]

Here I thought that the fiscal fiasco was limiting the operations of organizations like ICS-CERT and here they are publishing a paper on the very important topic of defense in depth. I eagerly clicked on the link provided and was taken to an abstract for the paper. There wasn’t anything really new in the abstract, but hoping that that was due to poor writing, I clicked on the link to the actual paper and I was taken to a .PDF document with the following title:

Recommended Practice:
Improving Industrial Control Systems Cybersecurity with Defense-In-Depth Strategies
October 2009 [emphasis added]

While this four year-old paper undoubtedly has some valuable information in it, advertising this as “Recently Published” smacks of the cheapest form of bait-and-switch advertising. The only saving grace is that falling for the tactic only cost me a couple of minutes of my time, not any cash out of pocket.

If ICS-CERT wanted to re-emphasize the information in this document; certainly a good idea in light of the information I blogged about this weekend; a suitable blurb explaining that fact would go a long way to getting people to actually read the document. I got no further than the date on the title page and exited the document.


The federal government has lost a lot of credibility in the last couple of weeks and silliness like this does little to remedy the situation.

Monday, February 7, 2011

A Look at Cyber Defense in Depth

The National Science Foundation (NSF) has an interesting notice in Monday’s Federal Register (available on the internet on Saturday) for a March 22nd workshop that is intending to look at the basic assumption that a cyber ‘defense in depth’ strategy is the best way to protect information systems. This is intended to be the first in a series of ‘Assumption Buster’ workshops.

There are a number of things that set this Federal Register Notice apart from the mainstream notice. First this isn’t the normal meeting notice where some organization is publishing a required meeting notice. It reads like more of a solicitation to form an organization. NSF is asking people to apply to participate in the workshop; requiring a resume/CV and a one-page opinion paper on the topic of defense-in-depth.

Another unusual aspect of this workshop is that NSF’s National Coordination Office (NCO) for the Networking and Information Technology Research and Development (NITRD) Program will be paying travel expenses for the selected participants. Most public meetings reported in the Federal Register expect public participants to pay their own expenses.

Of course, the most unusual aspect of this workshop is that it is intended to be an adversarial type of environment. The notice states that:

“The goal is to engage in robust debate of topics generally believed to be true to determine to what extent that claim is warranted. The adversarial nature of these debates is meant to ensure the threat environment is reflected in the discussion in order to elicit innovative research concepts that will have a greater chance of having a sustained positive impact on our cyber security posture.”
It’s nice to see that some people are interested in the competition of ideas. The confrontation of ideas is an important part of the scientific process. It is always a good idea to stop and question basic assumptions that we make about the use of technology from time to time.

This will be focusing on information systems, but I think it will be interesting for the control system community to take a look at the results from this workshop
 
/* Use this with templates/template-twocol.html */